Description
Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-09-22
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: Arbitrary Code Execution
Action: Immediate Patch
AI Analysis

Impact

Adobe Campaign Classic is impacted by an Improper Input Validation flaw that can lead to arbitrary code execution in the context of the current user. The vulnerability allows a low‑privileged attacker to remotely execute code without any user interaction. The exploit requires conditions beyond the attacker’s control, but when those conditions are met the attacker gains full control of the application instance and can further compromise the underlying system. This represents a high‑risk integrity breach and a complete loss of data protection for affected deployments.

Affected Systems

The affected product is Adobe Campaign Classic from Adobe. No specific version numbers are provided in the advisory, so any instance that matches the vendor and product name should be verified against Adobe’s official patch status.

Risk and Exploitability

The CVSS score of 8.5 categorises the flaw as High severity. The EPSS score is not available, indicating either no aggregated exploitation data or insufficient data points; the actual likelihood of exploitation is therefore uncertain. The vulnerability is not listed in the CISA KEV catalog, reducing immediate knowledge of being actively exploited. Nonetheless, the lack of user interaction and the potential breadth of damage make it a top‑priority risk, especially if the required external conditions can be satisfied by an attacker.

Generated by OpenCVE AI on September 22, 2026 at 18:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe Campaign Classic security patch or upgrade to the latest version as issued in the Adobe Security Bulletin
  • Configure application and server firewalls to block unexpected traffic to exposed campaign interfaces and restrict access to privileged network segments
  • Enable robust input validation at the application layer and enforce strict role‑based access controls to limit the privileges of all users, thereby reducing the impact scope if an exploit occurs

Generated by OpenCVE AI on September 22, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe campaign Classic
Vendors & Products Adobe
Adobe campaign Classic

Tue, 22 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Campaign Classic (ACC) | Improper Input Validation (CWE-20)
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Campaign Classic
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-22T17:40:00.852Z

Reserved: 2026-08-27T21:20:45.367Z

Link: CVE-2026-82003

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T18:17:20.887

Modified: 2026-09-22T19:05:50.323

Link: CVE-2026-82003

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:00:12Z

Weaknesses
  • CWE-20

    Improper Input Validation